Until the first stable release, security fixes are made on the default branch. After releases begin, this file will list supported release lines.
Do not open a public issue for a suspected vulnerability. Use GitHub's Security tab and choose Report a vulnerability to submit a private report to the maintainers.
Include affected versions or commits, reproduction steps, impact, and any suggested mitigation. Please allow the maintainers time to validate and prepare a coordinated fix before public disclosure.
Never include production credentials, access tokens, personal data, or private customer content in a report.